Serbian activists targeted with Pegasus and NoviSpy spyware; 29 MEPs urge slowing Serbia's EU accession
The Citizen Lab, SHARE Foundation and Amnesty International confirmed a zero-click NSO Group Pegasus infection on a Serbian student activist's iPhone (December 2025–January 2026) and a new detection-evading NoviSpy Android variant linked to Serbian…
Forensic analysis by the Citizen Lab, with the SHARE Foundation and Amnesty International peer review, confirmed with high confidence that a member of Serbia's student protest movement had an iPhone infected with NSO Group's Pegasus via a zero-click iMessage exploit between December 2025 and January 2026, granting full device access (messages, photos, microphone, camera) with no user interaction. The Citizen Lab believes the exploit was patched as of iOS 18.4.1, which Infosecurity Magazine reports was released in April 2025. SHARE has documented at least 14 Apple Threat Notification recipients across Serbia's student movement, civil society and opposition politics — including a member of Parliament, a local politician/councilor and student protesters — since December 2025 (The Record) or since early 2026 (Security Affairs); 11 additional alerted phones remain under forensic investigation. Targeting coincided with the March 2026 local elections (The Record, Security Affairs), which Infosecurity framed as occurring ahead of key 2026 election cycles. Amnesty Tech confirmed a new detection-evading NoviSpy Android variant — at least two cases per The Record, one device per Infosecurity Magazine and Security Affairs — found on a student activist's Android phone after Serbian authorities seized it during police questioning. NoviSpy requires physical access and is typically installed after police seize phones during detention; CyberScoop reports the evidence pointed to Serbian government authorities, while Pegasus attribution remains unassigned. Serbia's BIA intelligence agency dismissed the findings as sensationalism, and the Serbian government did not respond to CyberScoop's requests for comment. One victim's text messages were read live on a pro-government TV network, and Cellebrite cut ties with Serbia after its tools were used to install NoviSpy on detainees. SHARE calls it the largest documented surveillance wave in Serbia's history. The Citizen Lab treats Apple Threat Notifications as presumptive infections and urges forensic screening and Lockdown Mode. In response, 29 MEPs sent a letter on Friday (reported by CyberScoop on 2026-09-04) demanding Serbia's EU accession be slowed until an investigation into its spyware use is completed, urging European Commission President Ursula von der Leyen to cancel a planned visit to Serbia, calling the surveillance 'a direct state attack on democracy,' and demanding rule-of-law accountability conditions.
- Citizen Lab (with SHARE Foundation and Amnesty International peer review) confirmed a zero-click NSO Group Pegasus infection on a Serbian student activist's iPhone between December 2025 and January 2026, granting full device access with no…
- The iMessage zero-click exploit was believed patched as of iOS 18.4.1; Infosecurity Magazine reports that version was released in April 2025 (single-source dating).
- At least 14 Apple Threat Notification recipients were documented by SHARE across Serbia's student movement, civil society and opposition politics, including an opposition MP, a local politician/councilor and student protesters.
- 11 additional alerted phones remain under forensic investigation (The Record).
- Amnesty Tech confirmed a new detection-evading NoviSpy Android variant; The Record reports at least two cases, while Infosecurity Magazine and Security Affairs each report one device.
- NoviSpy requires physical access and is typically installed after police seize phones during detention; CyberScoop reports the evidence pointed to Serbian government authorities, while Pegasus attribution remains unassigned.
- Targeting coincided with the March 2026 local elections (The Record, Security Affairs); Infosecurity Magazine framed it as ahead of key 2026 election cycles.
- Serbia's BIA intelligence agency dismissed the findings as sensationalism; the Serbian government did not respond to CyberScoop's requests for comment.
Coverage timelineoldest first · each row is one article
- · 12d agoPegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone
Infosecurity Magazine· 55
Citizen Lab and SHARE Foundation confirm a Serbian student activist's iPhone was infected with NSO Group Pegasus via a zero-click iMessage exploit.